E
Eric Portenier
I have a Windows 2000 DC running both DHCP and DNS for my
network. I also have about 30 XP machines that NEED to
have group policies enforced on them. Here is what has
been happening. On the XP clients, the group policy will
not apply itself. I had thought that maybe it was because
the domain policy was propegating down and overriding the
OU policy, so I checkemarked the "no override" button,
but to no avail. So, by just playing around a bit, I went
into my network connection settings, into the TCPIP
settings, and instead of assigning an IP AND DNS server
automatically, I only had it assign the IP, and I typed
in the IP address of my domain controller, which is also
acting as my DNS server. This worked to apply the group
policy, but now my internet access is gone from those XP
client machines. But when I take out the DNS IP, I get
internet, but no policy. Is there a setting in my DNS
configuration that I am missing? I have both a "." DNS
zone and my "prep" zone... is this what is causing my
problems? I have recently deleted the "." zone as per
another response I received, and tried applying
the "prep" zone settings to the DNS settings on the xp
clients, but that is not working. I have only just added
the dns suffix to be "prep" on the clients... this does
not seem to be working though. I have also recently run
into the situation where I have put the ISP's DNS IPs in
the forwarder area, but even when the client is pointed
to the internal DNS, it is applying the GPO, but not
allowing any outside internet traffic. I CAN put the
external DNS IPs on the client and I think it will work
both ways, applying the GPO and allowing outside traffic,
but I REALLY don't want to do this with the external DNS
addresses. Now I do also have an ISA firewall... could
this also be causing a problem with the DNS? In that I am
also not able to do any recursive queries on external
servers from my internal DNS server? It always comes back
with a "FAIL." ALSO, does my DNS zone have to be
cathedral-prep.com instead of just prep, because that is
what our domain is? Thanks very much for all your answers
and help... I do appreciate it! It is quite important
that I get this working very soon, so any help that
anyone can provide would be GREATLY appreciated.
THank you!
If you have any specifics, please email me at
(e-mail address removed)
network. I also have about 30 XP machines that NEED to
have group policies enforced on them. Here is what has
been happening. On the XP clients, the group policy will
not apply itself. I had thought that maybe it was because
the domain policy was propegating down and overriding the
OU policy, so I checkemarked the "no override" button,
but to no avail. So, by just playing around a bit, I went
into my network connection settings, into the TCPIP
settings, and instead of assigning an IP AND DNS server
automatically, I only had it assign the IP, and I typed
in the IP address of my domain controller, which is also
acting as my DNS server. This worked to apply the group
policy, but now my internet access is gone from those XP
client machines. But when I take out the DNS IP, I get
internet, but no policy. Is there a setting in my DNS
configuration that I am missing? I have both a "." DNS
zone and my "prep" zone... is this what is causing my
problems? I have recently deleted the "." zone as per
another response I received, and tried applying
the "prep" zone settings to the DNS settings on the xp
clients, but that is not working. I have only just added
the dns suffix to be "prep" on the clients... this does
not seem to be working though. I have also recently run
into the situation where I have put the ISP's DNS IPs in
the forwarder area, but even when the client is pointed
to the internal DNS, it is applying the GPO, but not
allowing any outside internet traffic. I CAN put the
external DNS IPs on the client and I think it will work
both ways, applying the GPO and allowing outside traffic,
but I REALLY don't want to do this with the external DNS
addresses. Now I do also have an ISA firewall... could
this also be causing a problem with the DNS? In that I am
also not able to do any recursive queries on external
servers from my internal DNS server? It always comes back
with a "FAIL." ALSO, does my DNS zone have to be
cathedral-prep.com instead of just prep, because that is
what our domain is? Thanks very much for all your answers
and help... I do appreciate it! It is quite important
that I get this working very soon, so any help that
anyone can provide would be GREATLY appreciated.
THank you!
If you have any specifics, please email me at
(e-mail address removed)